Bug 18353 - owncloud new security issues fixed in 8.0.12
Summary: owncloud new security issues fixed in 8.0.12
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 5
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/686579/
Whiteboard: has_procedure advisory MGA5-32-OK MGA...
Keywords: validated_update
Depends on:
Blocks:
 
Reported: 2016-05-04 17:21 CEST by David Walser
Modified: 2016-05-07 00:02 CEST (History)
2 users (show)

See Also:
Source RPM: owncloud-8.0.10-1.mga5.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2016-05-04 17:21:47 CEST
ownCloud has released new versions on May 3:
https://owncloud.com/blog-owncloud-9-0-2-8-2-4-8-1-7-8-0-12-7-0-14-available/

Details haven't been posted to the changelog, but should be soon:
https://owncloud.org/changelog/

Security advisories aren't available yet, as usual.

Updated packages uploaded for Mageia 5 and Cauldron.

Advisory:
========================

Updated owncloud package fixes security vulnerabilities:

The owncloud package has been updated to version 8.0.12, which fixes
undisclosed security issues and other bugs.

References:
https://owncloud.com/blog-owncloud-9-0-2-8-2-4-8-1-7-8-0-12-7-0-14-available/
https://owncloud.org/changelog/
========================

Updated packages in core/updates_testing:
========================
owncloud-8.0.12-1.mga5

from owncloud-8.0.12-1.mga5.src.rpm
Comment 1 David Walser 2016-05-04 17:22:01 CEST
You can find testing information in Bug 16491.

Whiteboard: (none) => has_procedure

Comment 2 Brian Rockwell 2016-05-05 13:45:49 CEST
This is an upgrade of ownCloud for Linux localhost 4.1.15-desktop-2.mga5 #1 SMP Wed Jan 20 17:05:51 UTC 2016 x86_64 x86_64 x86_64 GNU/Linux

-------------
The following 2 packages are going to be installed:

- owncloud-8.0.12-1.mga5.noarch
- php-fileinfo-5.6.20-1.mga5.x86_64

5.3MB of additional disk space will be used.

19MB of packages will be retrieved.
-------------


Installed the packages.

-----------
http://127.0.0.1/owncloud

I get the following message:

ownCloud will be updated to version 8.0.12.

It performs the upgrade and I log in.  Go to my music library and click on "I want a new Drug"

It plays.

Working as designed

CC: (none) => brtians1

Comment 3 Brian Rockwell 2016-05-05 14:41:08 CEST
Linux localhost 4.1.15-desktop-2.mga5 #1 SMP Wed Jan 20 17:37:30 UTC 2016 i686 i686 i686 GNU/Linux

-------------installed fresh copy of owncloud, etc.-------------

To satisfy dependencies, the following package(s) also need to be installed:

- apache-2.4.10-16.3.mga5.i586
- apache-mod_php-5.6.21-1.mga5.i586
- libmbfl1-1.2.0-12.mga5.i586
- libonig2-5.9.5-3.mga5.i586
- libphp5_common5-5.6.21-1.mga5.i586
- libt1lib5-5.1.2-18.mga5.i586
- php-ctype-5.6.21-1.mga5.i586
- php-curl-5.6.21-1.mga5.i586
- php-dom-5.6.21-1.mga5.i586
- php-fileinfo-5.6.21-1.mga5.i586
- php-filter-5.6.21-1.mga5.i586
- php-ftp-5.6.21-1.mga5.i586
- php-gd-5.6.21-1.mga5.i586
- php-gettext-5.6.21-1.mga5.i586
- php-hash-5.6.21-1.mga5.i586
- php-iconv-5.6.21-1.mga5.i586
- php-ini-5.6.21-1.mga5.i586
- php-json-5.6.21-1.mga5.i586
- php-mbstring-5.6.21-1.mga5.i586
- php-openssl-5.6.21-1.mga5.i586
- php-pdo-5.6.21-1.mga5.i586
- php-pdo_sqlite-5.6.21-1.mga5.i586
- php-posix-5.6.21-1.mga5.i586
- php-session-5.6.21-1.mga5.i586
- php-sqlite3-5.6.21-1.mga5.i586
- php-suhosin-0.9.37.1-1.mga5.i586
- php-sysvsem-5.6.21-1.mga5.i586
- php-sysvshm-5.6.21-1.mga5.i586
- php-timezonedb-2016.1-1.mga5.i586
- php-tokenizer-5.6.21-1.mga5.i586
- php-xml-5.6.21-1.mga5.i586
- php-xmlreader-5.6.21-1.mga5.i586
- php-xmlwriter-5.6.21-1.mga5.i586
- php-zip-5.6.21-1.mga5.i586
- php-zlib-5.6.21-1.mga5.i586
- t1lib-config-5.1.2-18.mga5.i586
- webserver-base-2.0-8.mga5.i586

86MB of additional disk space will be used.




-----------------------------------------------------------------
confirmed version

urpmi owncloud
Package owncloud-8.0.12-1.mga5.noarch is already installed

----------------------

I was able to configure ownCloud and get a working site

able to open ownCloud_user_manual without issue.

---------------

working as designed.

Whiteboard: has_procedure => has_procedure MGA5-32-OK MGA5-64-OK

Comment 4 claire robinson 2016-05-05 17:33:55 CEST
Validating.

Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 5 claire robinson 2016-05-05 18:16:20 CEST
Advisory uploaded.

Whiteboard: has_procedure MGA5-32-OK MGA5-64-OK => has_procedure advisory MGA5-32-OK MGA5-64-OK

Comment 6 Mageia Robot 2016-05-05 18:27:30 CEST
An update for this issue has been pushed to the Mageia Updates repository.

http://advisories.mageia.org/MGASA-2016-0167.html

Status: NEW => RESOLVED
Resolution: (none) => FIXED

David Walser 2016-05-07 00:02:44 CEST

URL: (none) => http://lwn.net/Vulnerabilities/686579/


Note You need to log in before you can comment on or make changes to this bug.